
EC-CouncilCertified SOC Analyst
Domain 1Objective 2
SOC Components, Workflow, and Metrics CSA Practice Questions (Page 1)
Part of the Security Operations and Management domain, which makes up ~12% of our current practice bank.
41questions here
9free pages
3concepts
Questions 1–5
- 1
A SOC manager wants to evaluate the effectiveness of the incident response team. The team recorded the following times for a security incident: detection at 10:00, containment at 10:30, and resolution at 11:15. What is the Mean Time to Respond (MTTR) for this incident?
Select an answer first - 2
A SOC has a 24/7 operation with three shifts. The day shift handles most of the alert triage, while the night shift is understaffed. The manager notices that incidents detected during the night shift have a significantly higher MTTR. The goal is to reduce MTTR without increasing headcount. Which approach is most effective?
Select an answer first - 3
A SOC analyst is handling an alert that has been escalated to an incident. The incident response team has contained the threat and eradicated it from the affected systems. What is the next phase in the SOC workflow?
Select an answer first - 4
A SOC manager is evaluating the performance of the team. The team has an MTTD of 2 hours and an MTTR of 6 hours. The manager wants to improve the overall incident handling time. Which metric should the manager focus on to reduce the total time from incident occurrence to resolution?
Select an answer first - 5
A SOC team is experiencing a high volume of alerts, many of which are false positives. The manager wants to reduce alert fatigue and improve the efficiency of the analysts. Which action best addresses this issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.